HNHacker News
TopNewBestAskShowJobs

akdev1l

844 karma · joined October 27, 2023

submissionscomments
akdev1l··on Show HN: PanicLock – Close your MacBook lid disable TouchID –> password unlock
Notably macOS cannot do this
akdev1l··on FIM – Linux framebuffer image viewer
If you wanted a minimal terminal with graphical support then you should probably just run a minimal Wayland session with cage + terminal emulator

fbdev is not it, going through the DRM subsystem is much better

akdev1l··on Do you even need a database?
You can import csv files into in memory tables and query them or you can use the csv extensions

$ sqlite3 :memory:

.import myfile.csv mytable

SELECT * FROM mytable;

$ sqlite3 :memory:

SELECT *

FROM csv_read('myfile.csv');

akdev1l··on We gave an AI a 3 year retail lease and asked it to make a profit
If these guys succeed and this thing blows up, do you think they would not stop all this oversight and whatever “moral” boundaries they have now to make more money?

I do not.

akdev1l··on Put your SSH keys in your TPM chip
> hijack your ssh command so you'll touch it yourself, thinking you're authorizing something else than you actually are.

That doesn’t do anything at all.

1. If the attacker is redirecting you to a different host then ssh will simply refuse to connect due to known_hosts (I guess they could have added to that file too, redirect you to a honeypot and then hopefully you’ll run “sudo” before realizing but then at that point just hijack “sudo” itself in the local machine)

2. If the attacker is trying to let you connect and eavesdrop your connection to still credentials then that also still doesn’t work as the handshake for ssh is not vulnerable to replay attacks

The attacker could trick you into signing something I guess but then that still doesn’t do anything because secrets are not divulged at any point

I guess if the yubikey is also used for `sudo` then your attack makes more sense, as the attacker could prompt you to authenticate a sudo request when you call the evil `ssh`

akdev1l··on Put your SSH keys in your TPM chip
You don’t need Secretive, there is actually Apple native way

I put my ssh keys into the Mac’s TPM and now it asks for a password/touch ID when I use it.

Unfortunately I forget what commands I used

akdev1l··on PiCore - Raspberry Pi Port of Tiny Core Linux
what’s the problem with ostree?
akdev1l··on PiCore - Raspberry Pi Port of Tiny Core Linux
You can do this already from the initramfs
akdev1l··on Do you even need a database?
SQLite can do it
akdev1l··on Do you even need a database?
> end up re-implementing relational databases at the application level anyway

This is by design, the idea is that scaling your application layer is easy but scaling your storage/db layer is not

Hence make the storage dumb and have the application do the joins and now your app scales right up

(But tbh I agree a lot of applications don’t reach the scale required to benefit from this)

akdev1l··on Wacli – WhatsApp CLI: sync, search, send
> You can now use the same WhatsApp account on multiple devices at the same time, using your primary phone to link up to four devices. You’ll need to log in to WhatsApp on your primary phone every 14 days to keep linked devices connected to your WhatsApp account.

ref: https://faq.whatsapp.com/1317564962315842/?cms_platform=ipho...

> Use WhatsApp on your computer even when your phone is off.

ref: https://faq.whatsapp.com/378279804439436/?helpref=faq_conten...

akdev1l··on 5NF and Database Design
My brain has been blunted too far due to dynamodb and NoSQL storage usage and now I can’t even normalize anymore
akdev1l··on LittleSnitch for Linux
The way to make kernel modules is to submit them to the kernel. Not really sure what a “universal kernel module” really is.

Also that seems irrelevant because it seems this was implemented in eBPF so no kernel modules are required.

akdev1l··on Rescuing old printers with an in-browser Linux VM bridged to WebUSB over USB/IP
Oh I thought you were referring to the VM part

Anyway Apple created CUPS so it should support anything Linux does when it comes to printing

edit: looks like they didn’t create it, they just hired the guy who did and shipped it

akdev1l··on Rescuing old printers with an in-browser Linux VM bridged to WebUSB over USB/IP
wdym?

OSX has literally always been supported only on very limited hardware so how would it support anything else?

akdev1l··on Dropping Cloudflare for Bunny.net
>What if there's no mass export? No mass import? Or you need to reset 2FA?

1. For DNS we have standardized AXFR requests which the DNS provider needs to support as they are part of the DNS standard. There is not an option of not having that unless you have a really shitty provider that you should change anyway.

2. Same for Mass Import because again DNS already defines these things at the protocol level.

And resetting 2FA or whatever is just the cost of using any service

Personally I have used CF for ~10 years so I have saved $240 and I simultaneously use GitHub Pages and CF Pages for CDN because again I just need to give them a bunch of static files. Adding a third CDN provider would literally be a single command at the end of my build pipeline.

akdev1l··on Dropping Cloudflare for Bunny.net
>Cloudflare workers, R2, D1, etc., isn't going to be that easy.

And how is that related to me? My comment said (and the parent I replied to) mentioned DNS and CDN.

Now we add compute services, data storage, whatever D1 is and the other comment mentioned auth/authz

Are people not aware what CDN and DNS are?

akdev1l··on Dropping Cloudflare for Bunny.net
>Using ESI? VCL? Signed URLs or auth? Any other custom functionality? Are you depending on your provider's bot management features which are "CONTACT FOR PRICE" with other providers?

I have no idea what two of those acronyms mean. None of this is part of what a CDN offers.

Yes if you use DDoS protection, or cloudfare’s ZeroTrust or embrace $X proprietary features then what I said no longer applies.

I strictly said DNS and CDN.

akdev1l··on Dropping Cloudflare for Bunny.net
>I don't like free offerings, because what if they decide to charge someday? What if someone decides "free is not feasible, we start charging $20 per instance now".

You can just move to another provider at that point. At least when it comes to CDN and DNS there’s literally no vendor lock-in.

You can grab your dns records export them to csv and import somewhere else easily and a CDN is just a file server so you can just give your files to someone else easily.

akdev1l··on Iran threatens 'complete and utter annihilation' of OpenAI's $30B Stargate
No it doesn’t.

The post was replying to this:

>Iran doesn't use any of these to attack America.

This is false, as the post explained.

Saying “what about the US attacking Iran?” does not change the above being false. In fact the US attacking Iran does not change the above false either.

Even if we accept both things as true:

1. Iran has historically attacked the US 2. The US has historically destabilized/attacked Iran

It doesn’t change the fact that “Iran does not use any of these (proxy groups) to attack America” is a false statement.

Skip me with your emotional arguments because I’ll just think you’re posturing and just trying to advance your agenda :-)

akdev1l··on Iran threatens 'complete and utter annihilation' of OpenAI's $30B Stargate
“What about…?” Does not make for a good argument.
akdev1l··on Adobe modifies hosts file to detect whether Creative Cloud is installed
The fundamental issue is that installers shouldn’t exist

There’s no need to have an executable program just to essentially unzip some files to disk

akdev1l··on Age verification as mass surveillance infrastructure
Then you can give the tokens to whoever you want

that does happen with alcohol but it’s rare because well people don’t wanna go to jail for giving alcohol to a minor

So your proposal would have to come with liability towards the individual

akdev1l··on Age verification as mass surveillance infrastructure
The main thing that caused this ruckus was law passed in California not the UK

not that it matters because doxxing and harassing developers is not acceptable.

akdev1l··on Age verification as mass surveillance infrastructure
seems a lot of people already consumed this as truth.

In the meantime a FOSS maintainer who is just trying to put the pieces in place to comply with the law (as written) got doxxed and harassed.

I hate it here

akdev1l··on Eight years of wanting, three months of building with AI
You need to very specific and also question the output if it does something insane
akdev1l··on Ubuntu now requires more RAM than Windows 11
Yeah, Fedora ships systemd-oomd

It did eventually work to but it took a while. It also did not killed the culprit runaway processes somehow but it did kill enough stuff for me to regain control of the system.

akdev1l··on Ubuntu now requires more RAM than Windows 11
MacOS handles memory pressure better than Linux imo (at least for interactive use cases)

I have seen MacOS overcommit up to 50% of memory and still have the system be responsive.

Yesterday I filled up my ram accidentally on Fedora and even earlyoom took several minutes to trigger and in the meantime the system was essentially non-responsive

akdev1l··on Windows 95 defenses against installers that overwrite a file with an older one
I mean it looks like they did try to redirect writes somehow. They probably tried more sane options until they arrived here.

>there is no formal concept of an installer or package in Windows.

this one is on them, I think package managers already existed - doesn’t seem like there was ever a blocker for windows to have a package manager but Microsoft never bothered until very recently

akdev1l··on Windows 95 defenses against installers that overwrite a file with an older one
I think you guys read “unhinged” as way more negative than I meant.

Just because I am saying it’s unhinged doesn’t mean I don’t think it’s cool

I’ve never read any windows source so I can still contribute to wine but I’ve read the NT kernel is really high quality

← PreviousPage 3 of 13Next →